Skip to content

chore(deps): update go indirect dependencies - #112

Open
deckhouse-BOaTswain wants to merge 1 commit into
mainfrom
renovate/go-indirect-dependencies
Open

deckhouse-BOaTswain wants to merge 1 commit into
mainfrom
renovate/go-indirect-dependencies

Conversation

@deckhouse-BOaTswain

@deckhouse-BOaTswain deckhouse-BOaTswain commented Jun 1, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/cloudflare/cfssl v1.6.5 -> v1.7.1 age confidence
github.com/containerd/stargz-snapshotter/estargz v0.18.2 -> v0.19.0 age confidence
github.com/deckhouse/deckhouse/pkg/log v0.2.0 -> v0.2.1 age confidence
github.com/docker/cli v29.4.0+incompatible -> v29.8.2+incompatible age confidence
github.com/docker/docker-credential-helpers v0.9.3 -> v0.9.9 age confidence
github.com/evanphx/json-patch v5.9.0+incompatible -> v5.9.11+incompatible age confidence
github.com/fsnotify/fsnotify v1.9.0 -> v1.10.1 age confidence
github.com/fxamacker/cbor/v2 v2.9.2 -> v2.9.6 age confidence
github.com/go-logr/logr v1.4.3 -> v1.4.4 age confidence
github.com/go-openapi/jsonpointer v0.23.1 -> v0.24.0 age confidence
github.com/go-openapi/swag v0.25.5 -> v0.29.2 age confidence
github.com/go-openapi/swag/cmdutils v0.25.5 -> v0.29.2 age confidence
github.com/go-openapi/swag/conv v0.25.5 -> v0.29.2 age confidence
github.com/go-openapi/swag/fileutils v0.25.5 -> v0.29.2 age confidence
github.com/go-openapi/swag/jsonname v0.26.0 -> v0.29.2 age confidence
github.com/go-openapi/swag/jsonutils v0.25.5 -> v0.29.2 age confidence
github.com/go-openapi/swag/loading v0.25.5 -> v0.29.2 age confidence
github.com/go-openapi/swag/mangling v0.25.5 -> v0.29.2 age confidence
github.com/go-openapi/swag/netutils v0.25.5 -> v0.29.2 age confidence
github.com/go-openapi/swag/stringutils v0.25.5 -> v0.29.2 age confidence
github.com/go-openapi/swag/typeutils v0.25.5 -> v0.29.2 age confidence
github.com/go-openapi/swag/yamlutils v0.25.5 -> v0.29.2 age confidence
github.com/google/certificate-transparency-go v1.3.2 -> v1.3.3 age confidence
github.com/google/go-containerregistry v0.21.3 -> v0.22.1 age confidence
github.com/hashicorp/errwrap v1.0.0 -> v1.1.0 age confidence
github.com/itchyny/gojq v0.12.17 -> v0.12.19 age confidence
github.com/itchyny/timefmt-go v0.1.6 -> v0.1.9 age confidence
github.com/jmoiron/sqlx v1.3.5 -> v1.4.0 age confidence
github.com/mailru/easyjson v0.7.7 -> v0.9.2 age confidence
github.com/pelletier/go-toml v1.9.3 -> v1.9.5 age confidence
github.com/prometheus/client_golang v1.23.2 -> v1.25.0 age confidence
github.com/prometheus/client_model v0.6.2 -> v0.6.3 age confidence
github.com/prometheus/common v0.66.1 -> v0.72.0 age confidence
github.com/prometheus/procfs v0.16.1 -> v0.22.0 age confidence
github.com/sirupsen/logrus v1.9.4 -> v1.10.2 age confidence
github.com/sylabs/oci-tools v0.19.0 -> v0.20.2 age confidence
github.com/tidwall/gjson v1.19.0 -> v1.20.0 age confidence
github.com/tidwall/match v1.1.1 -> v1.2.0 age confidence
github.com/tidwall/pretty v1.2.0 -> v1.2.2 age confidence
github.com/vbatts/tar-split v0.12.2 -> v0.12.3 age confidence
github.com/weppos/publicsuffix-go v0.30.0 -> v0.50.3 age confidence
github.com/zmap/zlint/v3 v3.5.0 -> v3.7.2 age confidence
go.yaml.in/yaml/v3 v3.0.4 -> v3.0.5 age confidence
golang.org/x/net v0.58.0 -> v0.60.0 age confidence
golang.org/x/oauth2 v0.36.0 -> v0.37.0 age confidence
golang.org/x/sync v0.22.0 -> v0.23.0 age confidence
golang.org/x/sys v0.47.0 -> v0.48.0 age confidence
golang.org/x/term v0.45.0 -> v0.46.0 age confidence
golang.org/x/text v0.41.0 -> v0.42.0 age confidence
golang.org/x/time v0.11.0 -> v0.16.0 age confidence
gomodules.xyz/jsonpatch/v2 v2.4.0 -> v2.5.0 age confidence
gotest.tools/v3 v3.4.0 -> v3.5.2 age confidence
gotest.tools/v3 v3.5.1 -> v3.5.2 age confidence
k8s.io/api v0.35.8 -> v0.37.1 age confidence
k8s.io/apiextensions-apiserver v0.35.8 -> v0.37.1 age confidence
k8s.io/apimachinery v0.35.8 -> v0.37.1 age confidence
k8s.io/client-go v0.35.8 -> v0.37.1 age confidence
sigs.k8s.io/controller-runtime v0.23.3 -> v0.25.2 age confidence
sigs.k8s.io/structured-merge-diff/v6 v6.3.2 -> v6.4.2 age confidence

Release Notes

cloudflare/cfssl (github.com/cloudflare/cfssl)

v1.7.1

Compare Source

Changelog

v1.7.0

Compare Source

Changelog

  • 5c9bfdf Add scripts to regenerate {api,bundler,ubiquity}'s testdata
  • 2adc622 Create semgrep.yml
  • faaff55 Fixes #​1237 partially by updating test data certificates to be valid
  • dd8f9ef Github actions linter uses golangci-lint@​v1.57
  • adad8d8 Merge pull request #​1 from ang-cloudflare/fix-pr-1434-review-findings
  • 12a0add Merge pull request #​1055 from akoserwal/master
  • 361a3a5 Merge pull request #​1364 from cloudflare/dependabot/go_modules/golang.org/x/crypto-0.21.0
  • 03f2681 Merge pull request #​1365 from cloudflare/dependabot/go_modules/github.com/go-sql-driver/mysql-1.8.0
  • d6d030a Merge pull request #​1368 from cloudflare/dependabot/go_modules/github.com/google/certificate-transparency-go-1.1.8
  • 91b63b5 Merge pull request #​1395 from cloudflare/hrushikeshdeshpande-creating-semgrep-yml
  • cb0a0a3 Merge pull request #​1408 from mitch292/mitch292/certificate-transparency-go-bump
  • 730ee58 Merge pull request #​1409 from mitch292/mitch292/revert-ct-go-upgrade
  • 1c1bc0b Merge pull request #​1410 from mitch292/mitch292/1237-fix-test-cases
  • 6d2d0b2 Merge pull request #​1412 from mitch292/mitch292/fix-linting
  • b898d2f Merge pull request #​1415 from mitch292/mitch292/go-version
  • ed8df49 Merge pull request #​1416 from cloudflare/mschwarzl/dockerignore
  • 82408a1 Merge pull request #​1434 from elukey/master
  • e429e72 Merge pull request #​1436 from mitch292/fix-copy-extensions-security-bypass
  • 7d5fdbb Merge pull request #​1445 from ang-cloudflare/ang/SECENG-13957
  • e71a023 Merge pull request #​1447 from cloudflare/dianatran/goreleaser-v2
  • 800f0c5 Migrate goreleaser config to v2 and limit build parallelism
  • 62db351 Regenerate api's testdata
  • 214a154 Regenerate bundler's testdata
  • f8821d5 Regenerate ubiquity's testdata
  • 14f61be Revert "Upgrade certificate-transparency-go from v1.1.8 to v1.3.1"
  • 05f2d4f SECENG-13957: feat: add ML-DSA-44/65/87 post-quantum key support
  • 038e4d2 Update README
  • 2bc4eb0 Update READMe
  • 2312d45 Update certstore_development and sqlit_test dbs after testdata update
  • a40f86c Update repository to reflect required min go version of 1.20
  • d3645c1 Update semgrep.yml
  • 1a73d78 Upgrade certificate-transparency-go from v1.1.8 to v1.3.1
  • b4650b5 build(deps): bump github.com/go-sql-driver/mysql from 1.7.1 to 1.8.0
  • a421aee build(deps): bump github.com/google/certificate-transparency-go
  • d13ac5d build(deps): bump golang.org/x/crypto from 0.19.0 to 0.21.0
  • ea2095d fix: preserve regenerated fixture coverage
  • 8994bdd fix: prevent CSR extensions from overriding CA-managed key usage in copy_extensions
  • cd8a4de ignore .git to .dockerignore
containerd/stargz-snapshotter (github.com/containerd/stargz-snapshotter/estargz)

v0.19.0

Compare Source

Security Updates
  • CVE-2026-71482
  • CVE-2026-77395
    • To mitigate this issue, v0.19.0 requires a configuration change to the CRI setting. Specifically, the --image-service-endpoint=unix:///run/containerd-stargz-grpc/containerd-stargz-grpc.sock flag needs to be specified on kubelet. Refer to kubelet configuration section in docs/overview.md for details.
Notable Changes
docker/cli (github.com/docker/cli)

v29.8.2+incompatible

Compare Source

v29.8.1+incompatible

Compare Source

v29.8.0+incompatible

Compare Source

v29.7.2+incompatible

Compare Source

v29.7.1+incompatible

Compare Source

v29.7.0+incompatible

Compare Source

v29.6.2+incompatible

Compare Source

v29.6.1+incompatible

Compare Source

v29.6.0+incompatible

Compare Source

v29.5.3+incompatible

Compare Source

v29.5.2+incompatible

Compare Source

v29.5.1+incompatible

Compare Source

v29.5.0+incompatible

Compare Source

v29.4.3+incompatible

Compare Source

v29.4.2+incompatible

Compare Source

v29.4.1+incompatible

Compare Source

docker/docker-credential-helpers (github.com/docker/docker-credential-helpers)

v0.9.9

Compare Source

What's Changed
  • update to go1.26.7
  • Dockerfile: update to debian trixie, libgcc-12-dev, ubuntu 24.04 (noble)
  • README: remove Go Report Card badge
  • build(deps): bump docker/* actions
  • build(deps): bump actions/checkout from 6.0.3 to 7.0.1
  • build(deps): bump actions/setup-go from 6.4.0 to 7.0.0
  • build(deps): bump codecov/codecov-action from 6.0.1 to 7.0.0
  • build(deps): bump crazy-max/.github/.github/workflows/zizmor.yml from 1.10.0 to 1.11.0
  • build(deps): bump softprops/action-gh-release from 3.0.0 to 3.0.2

Full Changelog: docker/docker-credential-helpers@v0.9.8...v0.9.9

v0.9.8

Compare Source

What's Changed
  • update to go1.26.4
  • wincred: inline label, and append to existing
  • build(deps): bump actions/checkout from 6.0.2 to 6.0.3
  • build(deps): bump codecov/codecov-action from 6.0.0 to 6.0.1
  • build(deps): bump crazy-max/.github/.github/workflows/zizmor.yml from 1.7.1 to 1.10.0
  • build(deps): bump docker/bake-action from 7.1.0 to 7.2.0
  • build(deps): bump docker/setup-buildx-action from 4.0.0 to 4.1.0
  • build(deps): bump docker/setup-qemu-action from 4.0.0 to 4.1.0

Full Changelog: docker/docker-credential-helpers@v0.9.7...v0.9.8

v0.9.7

Compare Source

What's Changed
  • update to go1.26.3
  • ci: update zizmore action to v1.7.1

Full Changelog: docker/docker-credential-helpers@v0.9.6...v0.9.7

v0.9.6

Compare Source

What's Changed
  • update to go1.25.9
  • secretservice: allow building on openbsd
  • wincred: minor cleanups
  • Dockerfile: document build-args
  • Dockerfile: update golangci-lint to v2.11
  • Dockerfile: update xx to v1.9.0
  • ci: set default permissions and timeouts
  • ci: update actions
  • ci: pin actions by sha
  • ci: add zizmor workflow

Full Changelog: docker/docker-credential-helpers@v0.9.5...v0.9.6

v0.9.5

Compare Source

What's Changed
  • build(deps): bump actions/checkout from 5 to 6 #​395
  • build(deps): bump actions/upload-artifact from 4 to 6 #​398
  • build(deps): bump softprops/action-gh-release from 2.3.3 to 2.4.1 #​391
  • build(deps): bump softprops/action-gh-release from 2.4.1 to 2.5.0 #​397
  • Dockerfile: remove redundant DEBIAN_FRONTEND=noninteractive #​404
  • Dockerfile: update golangci-lint to v2.8 #​402
  • gha: update some actions to ubuntu 24.04 #​401
  • update to go1.25.2 #​392
  • update to go1.25.5 #​399

Full Changelog: docker/docker-credential-helpers@v0.9.4...v0.9.5

v0.9.4

Compare Source

What's Changed
  • update to go1.25.1 #​387
  • wincred: fix unsafe uintptr usage to be GC-safe on go1.25 #​386
  • gha: add macos-15-intel, remove macos-13 (deprecated) #​384
  • deb: Dockerfile: update to debian bookworm, ubuntu jammy (22.04) #​385
  • Dockerfile: update xx to v1.7.0 #​383
  • Dockerfile: update golangci-lint to v2.5 #​386
  • Dockerfile: merge build stages #​249
  • build(deps): bump github.com/danieljoos/wincred v1.2.3 #​388
  • build(deps): bump softprops/action-gh-release from 2.2.1 to 2.3.2 #​373
  • build(deps): bump actions/checkout from 4 to 5 #​376
  • build(deps): bump actions/setup-go from 5 to 6 #​377
  • build(deps): bump actions/github-script from 7 to 8 #​378
  • build(deps): bump softprops/action-gh-release from 2.3.2 to 2.3.3 #​379

Full Changelog: docker/docker-credential-helpers@v0.9.3...v0.9.4

evanphx/json-patch (github.com/evanphx/json-patch)

v5.9.11+incompatible

Compare Source

v5.9.10+incompatible

Compare Source

fsnotify/fsnotify (github.com/fsnotify/fsnotify)

v1.10.1

Compare Source

Changes and fixes
  • inotify: don't remove sibling watches sharing a path prefix (#​754)

  • inotify, windows: don't rename sibling watches sharing a path prefix
    (#​755)

v1.10.0

Compare Source

This version of fsnotify needs Go 1.23.

Changes and fixes
  • inotify: improve initialization error message (#​731)

  • inotify: send Rename event if recursive watch is renamed (#​696)

  • inotify: avoid copying event buffers when reading names (#​741)

  • kqueue: skip dangling symlinks (ENOENT) in watchDirectoryFiles, so a bad entry no longer aborts Watcher.Add for the whole directory (#​748)

  • kqueue: drop watches directly in Close() to fix a file descriptor leak when recycling watchers (#​740)

  • windows: fix nil pointer dereference in remWatch (#​736)

  • windows: lock watch field updates against concurrent WatchList to fix a race introduced in v1.9.0 (#​709, #​749)

fxamacker/cbor (github.com/fxamacker/cbor/v2)

v2.9.6

Compare Source

v2.9.6 fixes 12 bugs, including an important fix for apps that decode CBOR maps into Go maps, and has one behavior change. API is unchanged but more errors are detected.

Most of these bugs were identified while improving tests and reviewing code for an upcoming release.

Tests and fuzz tests were extended.

Upgrading to v2.9.6 from all prior versions is recommended.

🐞 Important Fix

Not affected:

  • Decoding data this codec encoded from the same Go map type, because this codec does not encode to CBOR null from Go values of bool, integer, float, or string kind.
  • Apps that don't decode a CBOR null or undefined map key or value into a Go map whose key or value type is of bool, integer, float, or string kind.
  • Decoding CBOR maps into structs (struct fields of map type follow the bullet above).
  • Decoding CBOR maps into map[any]any, and into any (with unchanged DefaultMapType).

For use cases outside the "not affected" list, decoding a CBOR null or undefined map key or value (including 55799(null)) into a Go map whose key or value type is of bool, integer, float, or string kind kept the previous map entry's key or value (instead of the zero value). See PR #​855 for details.

⚠️ Behavior change

Decoding CBOR null or undefined into an interface that holds a value now sets it to nil, matching encoding/json (v1 and v2). Previously, the interface kept its value (PR #​827), which was not the intended behavior.

What's Changed

Some of these bugs could only be triggered by incorrect usage in user apps, such as invalid struct tags or an unsupported DefaultByteStringType setting, etc. None of these bugs were reported by a project affected by them.

Decoding
Encoding
  • Fix encoding self-referencing types by @​fxamacker in #​833
  • Fix panic encoding marshaler of unsupported underlying types by @​fxamacker in #​834
  • Fix omitzero panic encoding struct field of unsupported underlying types implementing marshaler by @​fxamacker in #​835
  • Fix encoding TimeUnixMicro outside 1677 to 2262 by @​fxamacker in #​837
    • Encoded output also changes for some times within one second of either end of that range.
  • Reject encoding time.Time when Go formats wrong year by @​fxamacker in #​838
CI / GitHub Actions and Docs

Full Changelog: fxamacker/cbor@v2.9.4...v2.9.6

v2.9.5

Compare Source

This version was tagged from the wrong branch by mistake and is retracted.

Use v2.9.6 (https://github.com/fxamacker/cbor/releases/tag/v2.9.6) instead.

v2.9.4

Compare Source

This release fixes potential panics when decoding a CBOR map whose key decodes to an uncomparable Go value under certain conditions.

Not affected: user apps that don't register tag types and don't use map key types that are either named empty interfaces (e.g. type MyAny any) or contain interfaces.

These potential panics can be encountered when one of these two conditions is met:

  • user application registers a tag type (via TagSet interface) that is an array or struct with uncomparable or interface{} element or field type, or
  • user application specifies a destination Go map whose key type is a named empty interface type or a type containing an interface.

This was identified while improving tests and reviewing code for an upcoming release.

Tests and fuzz tests were extended to cover this bug.

Upgrading to v2.9.4 is recommended.

What's Changed

Full Changelog: fxamacker/cbor@v2.9.3...v2.9.4

v2.9.3

Compare Source

This release fixes a potential panic when decoding into a time.Time from a CBOR byte string, map, or array under certain conditions.

Not affected: standard CBOR time data (RFC 8949 tag 0 or tag 1), and decoders configured with timeTag = DecTagRequired.

Upgrading to v2.9.3 is recommended.

The panic stack trace was publicly reported on 2026-08-17, and the fix was released the same day. Fuzz testing was extended to cover this class of bug, and fuzzing of v2.9.3 is ongoing.

What's Changed

  • Skip data item when decoding to time.Time fails under certain conditions by @​fxamacker in [#​803](htt

Configuration

📅 Schedule: Branch creation - "before 06:00 on monday" in timezone UTC, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@deckhouse-BOaTswain deckhouse-BOaTswain added dependencies Pull requests that update a dependency file go Pull requests that update go code renovate indirect labels Jun 1, 2026
@deckhouse-BOaTswain

deckhouse-BOaTswain commented Jun 1, 2026 •

Copy link
Copy Markdown
Contributor Author

ℹ Artifact update notice

File name: examples/basic-example-module/hooks/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 5 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.25.8 -> 1.26.0
github.com/go-openapi/jsonreference v0.21.6 -> v1.0.0
github.com/klauspost/compress v1.18.5 -> v1.20.1
google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af -> v1.36.12
k8s.io/kube-openapi v0.0.0-20260603220949-865597e52e25 -> v0.0.0-20260721132016-d427ff9ee9ad
k8s.io/utils v0.0.0-20260507154919-ff6756f316d2 -> v0.0.0-20260626114624-be93311217bd
File name: examples/common-hooks/tls-certificate/hooks/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 7 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.25.8 -> 1.27
github.com/go-openapi/jsonreference v0.21.6 -> v1.0.0
github.com/klauspost/compress v1.18.5 -> v1.20.1
github.com/zmap/zcrypto v0.0.0-20230310154051-c8b263fd8300 -> v0.0.0-20260906180147-3ed30b1e9340
golang.org/x/crypto v0.55.0 -> v0.57.0
google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af -> v1.36.12
k8s.io/kube-openapi v0.0.0-20260603220949-865597e52e25 -> v0.0.0-20260721132016-d427ff9ee9ad
k8s.io/utils v0.0.0-20260507154919-ff6756f316d2 -> v0.0.0-20260626114624-be93311217bd
File name: examples/dependency-example-module/hooks/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 9 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.25.8 -> 1.26.0
github.com/google/go-containerregistry v0.21.3 -> v0.22.1
github.com/stretchr/testify v1.11.1 -> v1.12.1
k8s.io/api v0.35.8 -> v0.37.1
k8s.io/apimachinery v0.35.8 -> v0.37.1
github.com/go-openapi/jsonreference v0.21.6 -> v1.0.0
github.com/klauspost/compress v1.18.5 -> v1.20.1
google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af -> v1.36.12
k8s.io/kube-openapi v0.0.0-20260603220949-865597e52e25 -> v0.0.0-20260721132016-d427ff9ee9ad
k8s.io/utils v0.0.0-20260507154919-ff6756f316d2 -> v0.0.0-20260626114624-be93311217bd
File name: examples/example-module/hooks/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 8 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.25.8 -> 1.26.0
github.com/stretchr/testify v1.11.1 -> v1.12.1
k8s.io/api v0.35.8 -> v0.37.1
k8s.io/apimachinery v0.35.8 -> v0.37.1
github.com/go-openapi/jsonreference v0.21.6 -> v1.0.0
github.com/klauspost/compress v1.18.5 -> v1.20.1
google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af -> v1.36.12
k8s.io/kube-openapi v0.0.0-20260603220949-865597e52e25 -> v0.0.0-20260721132016-d427ff9ee9ad
k8s.io/utils v0.0.0-20260507154919-ff6756f316d2 -> v0.0.0-20260626114624-be93311217bd
File name: examples/settings-check/hooks/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 5 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.25.8 -> 1.26.0
github.com/go-openapi/jsonreference v0.21.6 -> v1.0.0
github.com/klauspost/compress v1.18.5 -> v1.20.1
google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af -> v1.36.12
k8s.io/kube-openapi v0.0.0-20260603220949-865597e52e25 -> v0.0.0-20260721132016-d427ff9ee9ad
k8s.io/utils v0.0.0-20260507154919-ff6756f316d2 -> v0.0.0-20260626114624-be93311217bd
File name: examples/single-file-app-example/hooks/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 7 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.25.8 -> 1.26.0
github.com/stretchr/testify v1.11.1 -> v1.12.1
k8s.io/apimachinery v0.35.8 -> v0.37.1
github.com/go-openapi/jsonreference v0.21.6 -> v1.0.0
github.com/klauspost/compress v1.18.5 -> v1.20.1
google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af -> v1.36.12
k8s.io/kube-openapi v0.0.0-20260603220949-865597e52e25 -> v0.0.0-20260721132016-d427ff9ee9ad
k8s.io/utils v0.0.0-20260507154919-ff6756f316d2 -> v0.0.0-20260626114624-be93311217bd
File name: examples/single-file-example/hooks/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 7 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.25.8 -> 1.26.0
github.com/stretchr/testify v1.11.1 -> v1.12.1
k8s.io/apimachinery v0.35.8 -> v0.37.1
github.com/go-openapi/jsonreference v0.21.6 -> v1.0.0
github.com/klauspost/compress v1.18.5 -> v1.20.1
google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af -> v1.36.12
k8s.io/kube-openapi v0.0.0-20260603220949-865597e52e25 -> v0.0.0-20260721132016-d427ff9ee9ad
k8s.io/utils v0.0.0-20260507154919-ff6756f316d2 -> v0.0.0-20260626114624-be93311217bd
File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 5 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.25.8 -> 1.26.0
github.com/stretchr/testify v1.11.1 -> v1.12.1
github.com/klauspost/compress v1.18.5 -> v1.20.1
github.com/zmap/zcrypto v0.0.0-20230310154051-c8b263fd8300 -> v0.0.0-20260906180147-3ed30b1e9340
golang.org/x/crypto v0.55.0 -> v0.57.0
google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af -> v1.36.12

@deckhouse-BOaTswain
deckhouse-BOaTswain force-pushed the renovate/go-indirect-dependencies branch 10 times, most recently from 5597e2e to 0a9ebc9 Compare June 10, 2026 02:43
@deckhouse-BOaTswain
deckhouse-BOaTswain force-pushed the renovate/go-indirect-dependencies branch 5 times, most recently from 966b08c to e101419 Compare June 17, 2026 09:42
@deckhouse-BOaTswain
deckhouse-BOaTswain force-pushed the renovate/go-indirect-dependencies branch 2 times, most recently from 6fe7c8f to 22269a7 Compare June 18, 2026 21:40
@deckhouse-BOaTswain
deckhouse-BOaTswain force-pushed the renovate/go-indirect-dependencies branch 8 times, most recently from 78d3cf1 to 0d8bc32 Compare July 1, 2026 12:29
@deckhouse-BOaTswain
deckhouse-BOaTswain force-pushed the renovate/go-indirect-dependencies branch 16 times, most recently from ea94f1e to 244d828 Compare July 14, 2026 22:04
@deckhouse-BOaTswain
deckhouse-BOaTswain force-pushed the renovate/go-indirect-dependencies branch 12 times, most recently from 1b8e0e4 to 7034be1 Compare July 23, 2026 06:46
@deckhouse-BOaTswain
deckhouse-BOaTswain force-pushed the renovate/go-indirect-dependencies branch from 7034be1 to a54e3f7 Compare July 24, 2026 08:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code indirect renovate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants